CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
8105 | CVE-2003-1281 | Candidate | cgihtml 1.69 allows local users to overwrite arbitrary files via a symlink attack on certain temporary files. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8104 | CVE-2003-1280 | Candidate | Directory traversal vulnerability in cgihtml 1.69 allows remote attackers to overwrite and create arbitrary files via a .. (dot dot) in multipart/form-data uploads. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8103 | CVE-2003-1279 | Candidate | S-PLUS 6.0 allows local users to overwrite arbitrary files and possibly elevate privileges via a symlink attack on (1) /tmp/__F8499 by Sqpe, (2) /tmp/PRINT.$$.out by PRINT, (3) /tmp/SUBST$PID.TXT and /tmp/ed.cmds$PID by mustfix.hlinks, (4) /tmp/file.1 and /tmp/file.2 by sas_get, (5) /tmp/file.1 by sas_vars, and (6) /tmp/sgml2html$$tmp /tmp/sgml2html$$tmp1 /tmp/sgml2html$$tmp2 by sglm2html. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8102 | CVE-2003-1278 | Candidate | Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into IMG tags. | Assigned (20051116) | None (candidate not yet proposed) | View | |
8101 | CVE-2003-1277 | Candidate | Cross-site scripting (XSS) vulnerabilities in Yet Another Bulletin Board (YaBB) 1.5.0 allow remote attackers to execute arbitrary script as other users and possibly steal authentication information via cookies by injecting arbitrary HTML or script into (1) news_icon of news_template.php, and (2) threadid and subject of index.html | Assigned (20051116) | None (candidate not yet proposed) | View |
Page 19323 of 20943, showing 5 records out of 104715 total, starting on record 96611, ending on 96615